Appearance
Authentication
API key
All API requests require the X-API-Key header.
X-API-Key: your-api-key-hereYour API key is available in Settings > Developer Tools > API Keys.
bash
curl https://app.docrunner.io/api/packets \
-H "X-API-Key: your-api-key-here"Failed authentication
Both cases return 401 Unauthorized.
| Situation | Response body |
|---|---|
| No key sent | { "error": "API key required" } |
| Key not recognized | { "error": "Invalid API key" } |
Regenerating your key
You can regenerate your API key from the Developer Tools page. This immediately invalidates the old key. All existing integrations using the old key stop working and must be updated.
Security notes
- Never put your API key in client-side code or a public repository.
- An API key has full access to your account's resources.
- Verify webhook deliveries with the signature header instead of trusting the request. See signature verification.